Exposure starts now
Encrypted data can be collected today for future decryption. The information may still be sensitive when its current protection can be broken.
Products / Assessment
AlphaA starting point for PQC migration.
QuantumSentinel provides a starting point for your organization's PQC migration that is backed up by your own network data and topology.
Quantum risk
Migration decisions depend on where cryptography is used, what it protects, and how long that information must stay confidential.
A sufficiently capable quantum computer could break widely used public-key encryption and digital signatures.
Source: NIST
Encrypted data can be collected today for future decryption. The information may still be sensitive when its current protection can be broken.
Cryptography can sit across application code, public connections, and internal services. An initial scan helps identify what is visible and where a wider assessment is needed.
QuantumSentinel
Start with one asset and review the cryptographic evidence it exposes. Use the findings to identify what needs further review, who owns it, and the next action.
Review observed TLS versions, cipher settings, key exchange, and certificate algorithms. The scan reports whether it observed post-quantum key exchange. It does not crawl pages or inspect the application.
Review cryptographic references in supported text files in a public GitHub repository. Findings include file and line evidence. Pattern matching does not execute code or prove how the application uses it.
Inspect one supported text file up to 512 KB. Use source or configuration content without secrets.
Run the local connector on an approved computer. It uploads the scan scope, responding addresses, service observations, and summary to the service. The browser cannot inspect a private network.
How it works
Select the asset and scan type. Confirm authorization.
Run the checks available for that type.
Review findings against the observed evidence and coverage limits.
Assign an owner and next action for findings that need follow-up.
This example is not a scan result.
Start with one asset you own or have permission to assess. Keep the target and scan type with the result.
A scan covers the evidence it observes. It is not a certification or a complete system assessment. Do not submit passwords, private keys, customer records, or other sensitive data.
Give your migration program an initial evidence base. Use findings to identify the questions, systems, and owners that need a wider assessment.
Focus follow-up work on observed cryptographic exposure. Check the evidence and scope before deciding which findings need action.
Locate cryptographic code that needs review in a public repository or supported file. Use the findings to plan changes with your team.
Compare responding services with your network inventory. Identify gaps in visibility and decide where a closer review is needed.
Get a starting point for a discussion with your hosting provider. Review what the public connection reveals about its cryptography.
Use an authorized initial scan to define follow-up questions with a client. Keep the observed findings separate from the wider assessment.